News
CVE-2025-4123 Grafana
This is a notice from the Information Security Office to alert you to a critical vulnerability that impacts Grafana. Please share this alert internally with IT admins and service owners who run the product so they are aware and know what actions to take to address this vulnerability.
Unauthorized PayPal Account Email - Phishing Email
We have received several reports of unrecognized, bogus PayPal account creation attempts using @berkeley.edu email addresses.
Drupal Core SQL Injection Vulnerability CVE-2026-9082
This is a follow-up to a notice alerting you to a critical vulnerability affecting sites running the Drupal Content Management System [1]. Please share this alert internally with IT admins and service owners who run the product so they are aware and know what actions to take to address this...
Drupal Core Vulnerability PSA-2026-05-18
ISO is aware of an upcoming critical security update that affects Drupal core. The Drupal Security Team has issued a heads-up (PSA-2026-05-18) about a highly critical security update coming out for Drupal core[1].
ISO Security Notice: NGINX Rift
ISO is aware of a critical vulnerability, codenamed NGINX Rift, that affects NGINX Plus and NGINX Open’s ngx_http_rewrite_module module, which is part of every standard NGINX build. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed...